control
500.4 — Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- framework
- nydfs-500
- type
- preventive
- category
- administrative
Details
- control_id
- 500.4
- framework
- nydfs-500
- group
- NYDFS 500 (NY Cybersecurity Regulation, 23 NYCRR 500)
- domains
- Governance, Policy & Oversight
- Risk Assessment & Management
- Access Control & Identity Management
- Vulnerability & Patch Management
- Logging, Monitoring & Detection
- Third-Party / Supply-Chain Risk
- Cryptography & Key Management
- Incident Management & Response
- Business Continuity & Disaster Recovery
- Awareness & Training
- risk_count
- 2
- control_type
- preventive
- control_category
- administrative
- automation
- manual
- key_control
- False
- requirement_status
- Not provided
- requirement_frequency
- Not provided
- source_url
- Not provided
- source_pages
- Not provided
Source
No record-specific source URL is provided.
Connections
- 500.4 — Chief Information Security Officer (CISO) belongs_to NYDFS Part 500
- UC-GOV-09 — Appoint accountable security leadership (CISO) maps_to 500.4 — Chief Information Security Officer (CISO)
- framework
- nydfs-500
- control_id
- 500.4
- coverage
- partial
- delta
- 500.4(c) also requires timely reporting of material cybersecurity issues, not only annual reports
- relationship
- intersects_with
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.